Out-of-Bounds Affecting suricata package, versions [0,4.1.4)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.5% (65th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-SURICATA-2384332
  • published26 Jan 2022
  • disclosed28 Aug 2019
  • creditUnknown

Introduced: 28 Aug 2019

CVE-2019-10056  (opens in a new tab)
CWE-119  (opens in a new tab)

How to fix?

Upgrade suricata to version 4.1.4 or higher.

Overview

Affected versions of this package are vulnerable to Out-of-Bounds. An issue was discovered in Suricata 4.1.3. The code mishandles the case of sending a network packet with the right type, such that the function DecodeEthernet in decode-ethernet.c is executed a second time. At this point, the algorithm cuts the first part of the packet and doesn't determine the current length. Specifically, if the packet is exactly 28 long, in the first iteration it subtracts 14 bytes. Then, it is working with a packet length of 14. At this point, the case distinction says it is a valid packet. After that it casts the packet, but this packet has no type, and the program crashes at the type case distinction.

References

CVSS Base Scores

version 3.1